VDB
RHSA-2024%3A4460
RHSA-2024%3A4460
PUBLISHED
CVSS 5.300000190734863 MEDIUM
A flaw was found in the io.netty:netty-codec-http package. Affected versions of this package are vulnerable to Allocation of Resources Without Limits or Throttling issues due to the accumulation of data in the HttpPostRequestDecoder. The decoder cumulates bytes in the undecodedChunk buffer until it can decode a field, allowing data to accumulate without limits. This flaw allows an attacker to cause a denial of service by sending a chunked post consisting of many small fields that will be accumulated in the bodyListHttpData list.
Risk Scores
CVSS 3.1
5.300000190734863
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Red Hat | Red Hat Data Grid |
Timeline
- Jul 10, 2024 CVE Published
- Apr 24, 2026 CVE Updated
- Apr 25, 2026 Distribution Patch
- Apr 25, 2026 Distribution Patch
- Apr 25, 2026 Security Advisory
- Apr 25, 2026 Security Advisory
- Apr 25, 2026 Security Advisory
References
- https://access.redhat.com/errata/RHSA-2024:4460 advisory
- https://access.redhat.com/security/updates/classification/#important advisory
- https://access.redhat.com/documentation/en-us/red_hat_data_grid/8.5/html-single/red_hat_data_grid_8.5_release_notes/index advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2270863 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=2272907 issue
- https://security.access.redhat.com/data/csaf/v2/advisories/2024/rhsa-2024_4460.json advisory
- https://access.redhat.com/security/cve/CVE-2024-29025 advisory
- https://www.cve.org/CVERecord?id=CVE-2024-29025 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2024-29025 advisory
- https://gist.github.com/vietj/f558b8ea81ec6505f1e9a6ca283c9ae3 advisory
- https://github.com/netty/netty/commit/0d0c6ed782d13d423586ad0c71737b2c7d02058c advisory
- https://github.com/netty/netty/security/advisories/GHSA-5jpm-x58v-624v advisory
- https://security.snyk.io/vuln/SNYK-JAVA-IONETTY-6483812 advisory
- https://access.redhat.com/security/cve/CVE-2024-29180 advisory
- https://www.cve.org/CVERecord?id=CVE-2024-29180 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2024-29180 advisory
- https://github.com/webpack/webpack-dev-middleware/security/advisories/GHSA-wr3j-pwj9-hqq6 advisory